Advancing AI-Enabled Cyber Defense for the U.S. Department of the Air Force
Across the defense community, cyber defenders are being asked to protect larger, more complex networks against adversaries that are moving faster and becoming harder to detect. For the Department of the Air Force, that challenge is especially urgent. The Department of the Air Force Information Network (DAFIN) supports more than 700,000 users, generating vast amounts of telemetry across a complexand constantly evolving digital environment.
At that scale, traditional cyber defense models can create significant operational strain. Analysts must connect signals across disconnected data sources, investigate alerts manually and respond to threats that may be designed to evade conventional security tools. The result is a growing need for capabilities that can help teams see across the environment more clearly, investigate faster, and move from reactive responseto proactive threat management.
World Wide Technology (WWT) is helping the U.S. Air Force address that need through the five-year, $40 million Artificial Intelligence-Enterprise Enabled Security Operations Center (AI-EESOC) IDIQ contract to deliver an Artificial Intelligence Security Operations Center capability for the 33rd Cyberspace Operations Squadron, which monitors DAFIN and plays a critical role in defending Air Force cyber operations.
By applying AI, automation and behavior-driven analytics to cyber defense, the initiative is designed to help analysts reduce manual workload, improve visibility across federated data sources, and accelerate threat detection and investigation, while keeping human decision-making at the center of mission-critical response.
Addressing the reality of modern cyber defense
AI has become critical as the speed and scale of the mission now exceed what manual processes alone can support. By helping analysts process large volumes of data, identify abnormal behavior, and prioritize the highest-risk activity, AI can enable cyber teams to operate more efficiently while sustaining the edge needed against advanced adversaries.
Bringing AI capabilities into the SOC
Through this contract, WWT is helping the Air Force integrate a dual-engine AI architecture designed to improve threat detection, investigation, and response. The approach moves beyond traditional tools by using behavior-driven analytics and autonomous investigation capabilities to enable analysts to identify and act on threats more quickly.
Key components include:
- Agentic Behavioral Analytics (Eagle6): Uses AI and machine learning to analyze network telemetry and packet capture (PCAP) data, autonomously build a precise digital topology map of the network and establish behavioral baselines. By understanding what normal activity looks like across the environment, the platform can help identify abnormal or potentially malicious behavior that may be missed by signature-based detection methods.
- Autonomous Investigative and Triage (Crogl): An autonomous investigator that works alongside the analyst, Crogl writes the queries against the data the customer already runs, correlating evidence, and reconstructing timelines without re-ingesting anything into a central database. The data stays where it lives and nothing leaves the customer's environment. Customers control which models Crogl uses, from frontier providers to self-hosted open-weight models, including fully air-gapped deployments. Crogl documents every step and produces natural language summaries with recommended actions, while the analyst makes the call.
"This partnership confirms that Crogl serves customers with the hardest security missions, and puts humans in control" — Monzy Merza, Founder and CEO, Crogl
Together, these capabilities are designed to reduce the time analysts spend on manual triage and investigation. Work that may have taken days can be compressed into minutes, allowing teams to focus on higher-priority decisions and mission-critical response actions.
The goal is not to replace analysts, but to give them better visibility, faster insights and a more complete view of activity across the network.
Advancing the future of federal cyber operations
This project represents an important milestone in the Department of War's Enterprise Agents Pacesetting Initiative, which is focused on accelerating the adoption of AI-enabled capabilities across enterprise operations. By using commercial solutions and rapid experimentation, the initiative helps move critical cyber capabilities from planning to operational alerts in months rather than years, by passing slower traditional software development cycles and demonstrating a more modern, agile approach to warfighting capability transformation.
For WWT, the initiative reinforces our role as an operational pathfinder for emerging federal cyber capabilities, bringing together deep defense experience, technical expertise and proven integration capabilities to help defense organizations evaluate new technologies, validate them in mission-relevant environments and scale solutions where they can deliver measurable operational value.
Building a blueprint for SOC transformation
The long-term vision for this project is to create a blueprint for broader Security Operations Center (SOC) transformation across the Department of War (DoW). By standardizing AI-driven insights and deploying autonomous agent sacross cyber workflows, the initiative aims to reduce investigation time, lower operational burden, and improve cyber readiness at scale. These capabilities can be extended enterprise-wide, helping cyber forces stay prepared for advanced threats and strengthening the Department's ability to maintain cyberspace dominance.
As the cyber threat landscape continues to evolve, defense organizations will need capabilities that are faster, more adaptive, and easier to scale. This initiative is a step toward that future, one where human analysts are supported by AI-enabled tools that help them stay ahead of the mission.